• I’m really surprised that Migro is asking for the production database credentials on the staging site.

    Our site is hosted on a server that doesn’t allow remote access to the database, which is completely standard and secure. On top of that, our staging site is hosted on a local machine connected to the internet.

    We can’t use Migro, but more importantly, given these security practices, we strongly advise against using Migro on your websites.

    Why did you choose to connect directly to the production database to handle the migration instead of using the WordPress REST APIs?

    Thank you for your clarification.

Viewing 1 replies (of 1 total)
  • Hi Patrice, I have answered this in full in your support ticket, including a configuration that works with your setup today. Briefly, for anyone reading here:

    Core REST cannot carry a content migration. It only exposes post meta a developer registered with show_in_rest, and refuses protected keys outright, so most theme and plugin custom fields are unreachable, as is the marker Migro writes so the next migration updates a post rather than duplicating it.

    For most users no remote database access is involved at all: staging and production sit on the same server and the connection is local, over localhost or a socket. Migro never asks a host to expose MySQL to the internet and has no mechanism to do so. Credentials never leave your site, are never sent to us or to any third party, and are encrypted at rest with libsodium under a key derived from your wp-config salts, so a stolen database dump yields nothing.

    Where the two sites are on separate machines, as in your case, an SSH tunnel works today and production’s MySQL stays closed to the internet. A connection mode needing only a site URL and a WordPress application password is also in active development.

    The exact commands are in the support thread.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this review.